update filter image
This commit is contained in:
@@ -35,7 +35,11 @@ detection:
|
||||
- '\rundll32.exe'
|
||||
- '\inetsrv\iissetup.exe'
|
||||
- '\inetsrv\appcmd.exe'
|
||||
Image|contains: 'c:\windows\'
|
||||
Image|startswith: 'C:\Windows\'
|
||||
filter_programfiles:
|
||||
Image|startswith:
|
||||
- 'C:\Program Files\'
|
||||
- 'C:\Program Files (x86)\'
|
||||
filter_update:
|
||||
CommandLine|startswith: 'C:\$WinREAgent\Scratch\'
|
||||
CommandLine|contains: '\dismhost.exe {'
|
||||
|
||||
Reference in New Issue
Block a user